I haven't used this so I'm not sure what's going on, but I believe OAuth involves a redirect back to servers controlled by the third party to actually do something with the authentication token. This doesn't strike me as necessarily fishy.
I would have thought the whole point of an app like this is to take advantage of the benefits of native UI, not to add yet another point of failure.